Red Hat Bugzilla – Bug 1582346
CVE-2018-10840 kernel: Heap-based buffer overflow in fs/ext4/xattr.c:ext4_xattr_set_entry() with crafted ext4 image
Last modified: 2018-08-28 18:44:09 EDT
The Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image. Upstream bug: https://bugzilla.kernel.org/show_bug.cgi?id=199347 Upstream patch: https://bugzilla.kernel.org/attachment.cgi?id=276147&action=diff https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8a2b307c21d4b290e3cbe33f768f194286d07c23
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1582348]